Overview
OpenAtlas 8.11.0 included a privileged default account with known or hard-coded credentials. If such an account remains active, an attacker needs no further exploit: the login itself provides access.
Technical findings
No complex exploit is required. The issue is a privileged default account with credentials that are publicly known or embedded in the product.
Because the account has administrative permissions, a successful login is a major compromise. The attacker gains the functionality and data access available to an OpenAtlas administrator.
The CVE record identifies hard-coded and default credentials as the relevant weakness categories. My advisory lists OpenAtlas 8.12.0 as the fixed release.
Why it matters
If an instance is accessible and default credentials have not been removed or changed, no other vulnerability is needed. A successful login gives direct access to an administrative account.
Potential impact
- A default login may remain usable with administrative privileges if no password change is enforced.
- Full compromise of the application may be possible immediately.
Remediation
- Upgrade to OpenAtlas 8.12.0 or later.
- Immediately rotate all known default and administrator credentials.
- Products should not ship with universal production passwords; initial credentials must be unique to each deployment and changed at first login.
- Where supported, further protect administrative access with MFA, network segmentation and monitoring.
Affected and fixed versions
Disclosure timeline
- Discovery
Discovered during an on-premises assessment.
- Initial contact
Initial contact (redacted@).
- Report submission
Consent obtained for unencrypted delivery of the report.
- Report sent
Report submitted to the vendor.
- Vendor feedback
Vendor communicated the fix.
- Retest
Retest successful; report updated.